Risk Tolerance
Risk tolerance determines how demanding the model is when translating numeric risk scores into labels like Low, Medium, High, and Extreme. It controls the thresholds at which a vendor’s score crosses from one label to the next. VISO TRUST offers three predefined tolerance levels:Minimal
Default. The strictest setting. High-assurance artifacts (independent audits, certifications) are required to move a vendor into the lowest risk tier. Best for organizations in regulated industries or those handling highly sensitive data with mature TPRM programs.
Moderate
Balances security rigor with operational efficiency. Strong controls are expected but there’s more flexibility in the assurance level required. Suited for mid-sized or fast-growing organizations with dynamic vendor portfolios.
Significant
Accepts a higher level of risk in exchange for speed and flexibility. Focus is on core security controls, with questionnaire responses accepted as primary evidence. Suited for less regulated industries or early-stage TPRM programs.
Changing risk tolerance affects how existing scores are displayed — a vendor currently labeled “Low” under Minimal tolerance may appear “Low” or even lower under Significant. Review your portfolio after changing this setting to understand the impact.
Risk Label Names
The default labels — No Context, Low, Medium, High, Extreme — can be renamed to match your organization’s risk vocabulary. If your GRC framework or executive reporting uses different terminology, updating the labels ensures consistency. To rename labels, open the risk tolerance customization in Settings → Risk Model and edit the Custom label field for each level. Label name changes are cosmetic only — they don’t affect the underlying scoring or thresholds.Control Domain Weighting
The VISO TRUST risk model weights control domains based on their relevance to a given relationship type. A vendor with network access is scored differently from one with only data access. For organizations using Custom Frameworks, control domain weighting can be adjusted to reflect your program’s priorities — for example, placing greater weight on privacy controls for vendors handling personal data.Risk Overrides
When an assessment is in Review Risk status, Org Admins can manually override the inherent or residual risk value calculated by the model. Use this when:- Compensating controls have been implemented that aren’t captured in the assessment
- The relationship context doesn’t fully reflect the actual risk exposure
- A business decision warrants accepting a different risk level than the model suggests
Compliance Certification Influence
By default, VISO TRUST gives partial credit when a vendor publicly claims a compliance certification (e.g., displays a SOC 2 badge on their website) but hasn’t provided the actual report. This reduces residual risk slightly, with lower assurance than a validated artifact. You can disable this behavior so that compliance certifications only count when the actual report is submitted and reviewed. Go to Settings → Risk Model to manage this setting.What the Risk Model Doesn’t Do
- It doesn’t replace human judgment. Risk overrides, context configuration, and remediation decisions are all made by your team.
- It doesn’t assess vendors you don’t have relationships with. Scores only exist for vendors in your portfolio.
- It doesn’t guarantee outcomes. Risk scores reflect the evidence collected — they’re as accurate as the data behind them.